BlockMyself
Guardrails

Start with built-in controls.

Use the device's native controls first. They are easier to maintain, easier to explain to a trusted person, and give you a clean base before adding DNS, router, policy, or lockout layers.

Exact menus Built-in first Test every browser

Before you start

  1. Update the device first so menu names match current documentation.
  2. Remove unused accounts and browsers before you configure filtering.
  3. Decide whether you will remember the passcode or whether a trusted person will hold it.
  4. After each device setup, test a blocked site in every browser that remains installed.
If you can undo the setup from the same daily account, treat this as a first layer only. Move next to Friction or Lockout.

iPhone / iPad

Use Screen Time. For a stronger setup, have the trusted person set the Screen Time passcode and avoid saving the Apple account password on the device.

Turn on Screen Time and set a passcode
  1. Open Settings.
  2. Tap Screen Time.
  3. Tap App & Website Activity and turn it on. On older versions this is a single Turn On Screen Time button.
  4. Tap Lock Screen Time Settings or Use Screen Time Passcode.
  5. Let the trusted person enter a passcode you do not know, if you are using the self-lockout model.
  6. When iOS asks for an Apple Account for Screen Time Passcode Recovery, enter the trusted person's Apple Account, not your own, and only if its password is one you have never seen. Skipping the prompt is the stronger choice, at a cost: with no recovery account, a forgotten passcode means erasing the device, so the trusted person must store it well. See The trusted person.
This step decides whether the passcode holds.

Whoever's Apple Account was entered at Passcode Recovery can reset the Screen Time passcode later with just that account's email and password, using Forgot Passcode?. If it is your own account, you can undo the lock alone at any time and the handoff is decorative. The recovery account can be different from the one signed in on the device, so it costs nothing to use the trusted person's. See Apple's passcode recovery documentation and the Recovery audit.

Block adult web content
  1. Open Settings -> Screen Time.
  2. Tap Content & Privacy Restrictions.
  3. Turn Content & Privacy Restrictions on.
  4. Tap App Store, Media, Web, & Games. On some versions, tap Content Restrictions instead.
  5. Tap Web Content.
  6. Choose Limit Adult Websites for the normal adult-content block.
  7. Choose Only Approved Websites for allowlist mode, which is the stronger option. Older versions of iOS call this Allowed Websites Only. See Allowlist mode for what it covers and what it costs day to day.
  8. Under Never Allow, add domains that are personally risky for you.
  9. Test in Safari, then test in every other browser still installed.
Stop easy app and setting changes
  1. Go back to Content & Privacy Restrictions.
  2. Open App Installations & Purchases. On older versions this is iTunes & App Store Purchases, reached through App Store, Media, Web, & Games.
  3. Set Installing Apps to Don't Allow.
  4. Set App Marketplaces to Don't Allow if shown. In the EU and Japan this is a second install path, and leaving it open lets you sideload a browser around the block.
  5. Set Deleting Apps to Don't Allow if deleting the blocker or browser is a bypass.
  6. Set In-app Purchases to Don't Allow if spending or subscriptions are part of the problem.
  7. Open Allowed Apps & Features and turn off apps you do not want available. Note that turning Safari off here only hides the icon: web pages opened inside other apps keep working, so this is not a web block on its own. The Web Content setting is the one that reaches those views.
  8. Open Passcode Changes and set it to Don't Allow if shown.
  9. Open Account Changes and set it to Don't Allow if shown.
  10. Open Cellular Data Changes and set it to Don't Allow if switching networks is part of the bypass.

For serious lockout, Screen Time alone is not enough if you can recover the passcode yourself. Use the Trusted person handoff.

Add a blocker the passcode protects (iOS 26.4 and later)

Blockers built on Apple's Screen Time framework (Opal, Jomo, ScreenZen, Brick, one sec, Refocus and others) ask for Screen Time access when first opened. Their blocks are enforced by iOS, so they hold when the app is closed, and since iOS 26.4 switching that access off under Settings -> Screen Time -> Apps with Screen Time Access can require the Screen Time passcode, provided Lock Screen Time Settings and Content & Privacy Restrictions are both on. With Deleting Apps set to Don't Allow, that is the first time a third-party blocker on an unsupervised iPhone genuinely resists self-removal.

  1. Pick a blocker with a strict mode that a second person can hold, and let the trusted person set its PIN.
  2. Confirm the protection on your device: try to switch the app's access off and note what you are asked for. On iOS 26.4 to 26.6 some users were asked for Face ID instead; the fix is reported in iOS 27.
  3. Turn off Share Across Devices unless every device on the account is set up just as strictly.
  4. Set the Apps rating limit under App Store, Media, Web, & Games to 16+ or lower. iOS 26 rates apps 13+, 16+ and 18+, and the web filter does not reach what native apps show in their own feeds.

The full stack, and how it fits with the DNS profile, is in what actually holds on an unsupervised iPhone.

Android

Use Google Family Link first. Android menus vary by manufacturer, but Family Link keeps most controls in one parent-side dashboard.

Read this before you plan around Family Link.

Family Link supervision only applies to Google Accounts under 18. Google offers supervision only for accounts under 18; there is no supported way to put an adult's account under someone else's Family Link control. If you are an adult setting this up for yourself, treat the Family Link steps below as guidance for a device you administer for someone else, and build your own setup on the device-level and network-level layers instead: Android Friction, router and DNS enforcement, and a trusted person holding the credentials described in Lockout. See Google's supervision documentation.

Set up Family Link
  1. Install Google Family Link on the parent or trusted person's device.
  2. Sign in with the parent Google Account.
  3. On the managed Android phone or tablet, sign in with the supervised Google Account.
  4. Follow the prompts to link the device to Family Link.
  5. Do not save the parent Google password on the managed device.
  6. Remove any second Google Account that can install apps or change settings without approval.
Filter Chrome, Search, and YouTube
  1. On the parent device, open Family Link.
  2. Select the supervised account.
  3. Tap Controls.
  4. Tap Google Chrome and Web (older versions call it Google Chrome or Chrome & Web).
  5. Choose Try to block explicit sites for the normal filter.
  6. Choose Only allow approved sites for whitelist mode.
  7. Add known risky domains to Blocked sites.
  8. Turn on SafeSearch for Google Search.
  9. Turn on Restricted Mode for YouTube, then test the YouTube app and YouTube in the browser.

Chrome filtering is not the same thing as whole-device filtering. If another browser, VPN, or private DNS setting remains available, add the Android Friction steps.

Limit app installs and browser bypasses
  1. In Family Link, open Controls -> Google Play.
  2. Set content restrictions for apps, games, movies, books, and purchases.
  3. Require approval for new app installs and purchases.
  4. Uninstall extra browsers, VPN apps, proxy apps, and app stores you do not need.
  5. Check Settings -> Apps for browsers hidden under unfamiliar names.
  6. Open Settings -> Network & internet -> Private DNS and note whether a DNS layer is already set.
  7. Test over Wi-Fi and mobile data. A router filter will not protect mobile data.

Chromebook / ChromeOS

ChromeOS is easier to lock down when the owner account and sign-in rules are controlled by the trusted person. Guest browsing is the common bypass to remove first.

Add the managed account
  1. Set up the Chromebook with the account that should be the owner, ideally the trusted person's account for stronger lockout.
  2. Add the supervised account that will be used daily.
  3. Use Family Link for that supervised account. Note the age limit described in the Android section: an adult account cannot be supervised.
  4. Do not use the owner account for daily browsing.
  5. Do not save the owner or parent password where the daily user can access it.
Turn off guest browsing and limit sign-in
  1. Sign in as the Chromebook owner.
  2. Open Settings.
  3. Open Privacy and security. On older builds this is Security and Privacy.
  4. Open Manage other people.
  5. Turn off Guest browsing.
  6. Turn on Limit who can sign-in. On older builds this is Restrict sign-in to the following users.
  7. Add only the accounts that should be allowed on the device.
  8. Sign out and confirm that guest mode is no longer available from the login screen.
These settings do not survive a Powerwash.

On a personal, unenrolled Chromebook anyone at the sign-in screen can press Ctrl + Alt + Shift + R to Powerwash the device, and the first account signed in afterward becomes the new owner. That resets guest browsing and sign-in limits in a couple of minutes with no password. Treat owner-account control as Guardrails-level friction, not lockout. Only enterprise or school enrollment with forced re-enrollment survives a Powerwash.

Filter the supervised account
  1. On the parent or trusted person's device, open Family Link.
  2. Select the supervised account.
  3. Open Controls -> Google Chrome and Web (older versions call it Google Chrome or Chrome & Web).
  4. Choose Try to block explicit sites or Only allow approved sites.
  5. Open Site settings and tighten permissions for downloads, pop-ups, extensions, and notifications where available.
  6. Test the daily account, then try to sign in as a different account and confirm it is blocked.

For school or organization-grade control, use Chrome Enterprise or another managed-device setup instead of relying only on a personal owner account.

Windows

Use Microsoft Family Safety, keep the daily account standard, and keep administrator rights away from the person who is trying not to bypass.

Family Safety works on adults, and this is the lever the phones lack. Microsoft lets a family organizer manage the safety settings of an adult member: web and search filters, screen time, and app and game filters. Only the organizer can change those settings, and a member cannot leave the family group on their own. So if the trusted person is the organizer and you are a member, the filter is theirs to switch off, not yours, with no fake birthdate involved. Two caveats: Microsoft says it is working on letting adult members opt out in a future update, so pair this with the standard-account split rather than relying on it alone; and the web filter only covers Edge, though the app filter can block other browsers as apps.
Create the family setup
  1. Go to account.microsoft.com/family.
  2. Sign in with the organizer account.
  3. Add the managed Microsoft account as a family member.
  4. On the Windows PC, sign in with the managed account.
  5. Open Settings -> Accounts -> Family or Family & other users.
  6. Confirm the managed account is a Standard User, not an administrator.
  7. Use a separate administrator account for setup and recovery.
Turn on web and search filtering
  1. Open the Family Safety dashboard.
  2. Select the family member.
  3. Open Content filters.
  4. Turn on Filter inappropriate websites and searches.
  5. Turn on Only use allowed websites if you want whitelist mode.
  6. Add personally risky domains to the blocked list.
  7. Use Microsoft Edge for the managed account.
  8. Set Edge as the default browser.
  9. Test the filter in Edge and then test any other installed browser.

Microsoft Family Safety web filtering is Edge-centered. Turning on Filter inappropriate websites and searches is intended to block other browsers on Windows and Xbox, but Microsoft's current documentation no longer promises this, so verify it on the actual device rather than assuming. Portable browsers, less common browsers, and any session where the managed account is not signed in can still get through. If Chrome, Firefox, Brave, portable browsers, or app stores remain available, add the Windows Friction steps.

Limit apps and installs
  1. In Family Safety, open Apps and games.
  2. Set age limits and app restrictions.
  3. Remove extra browsers from the standard account.
  4. Open Settings -> Apps and uninstall browsers or stores you do not need.
  5. Keep the Microsoft Store and installer approvals under the organizer or administrator account.
  6. Do not type the admin password into prompts while the daily user is watching or recording it.

Mac

Use Screen Time first. For stronger lockout, daily use should be a standard account and the trusted person should hold the admin password or Screen Time passcode.

On a Mac, Screen Time web filtering only covers Safari.

This is the most important thing to understand about blocking on macOS, and it is different from iPhone. On iPhone the filter sits underneath the browser, so it catches Chrome and Firefox too. On Mac it works through an opt-in programming interface that a browser has to adopt deliberately. Safari adopts it. Chrome, Firefox, Edge, and Brave do not, so Limit Adult Websites and Allowed Websites Only do nothing in those browsers. Embedded web views inside other Mac apps are not covered either.

Worse, macOS has no way to stop you installing one. The Mac's Screen Time pane does show Installing Apps, but under "Allowed on iOS": it governs a family member's iPhone, not Mac installs. On a Mac a standard user can drag a browser into their own home folder, or simply run it straight out of Downloads, without ever touching an admin password.

The same is true of any DNS filtering you add: a Mac appears to offer no on/off switch for a configuration profile, but an administrator can still change DNS servers directly or remove the profile, so only the administrator password stands in the way. That makes the standard-account step the real control on a Mac rather than a formality. So treat Mac Screen Time as a layer that works only if Safari is the only browser present and you are not actively looking for a way around it. If a Mac is where you actually bypass, the load-bearing layers are DNS filtering, router enforcement, and browser policy for any browser you keep, because those do not care which browser is running.

Turn on Screen Time
  1. Open System Settings.
  2. Click Screen Time.
  3. Turn on App & Website Activity. On older versions of macOS this is a single Screen Time on/off switch.
  4. Click Lock Screen Time Settings or set the Screen Time passcode if your macOS version shows that option.
  5. Let the trusted person hold the passcode if this is a self-lockout setup.
  6. As on iPhone, if macOS offers an Apple Account for passcode recovery, use the trusted person's account. Do not skip it, for the reason given above.
Set web, app, and store restrictions
  1. In System Settings, open Screen Time.
  2. Open Content & Privacy.
  3. Turn Content & Privacy on.
  4. Open App Store, Media, Web, & Games, then find the Safari section. macOS labels this section Safari, not Web Content as on iPhone.
  5. Set it to Limit Adult Websites.
  6. Use Allowed Websites Only if you want whitelist mode. On macOS each entry needs both a title and a URL.
  7. Tighten app, movie, TV, book, and store restrictions where relevant.
  8. Open App & Feature Restrictions and turn off apps or features you do not want available.
  9. Open Preference Restrictions and prevent changes that would weaken the setup.
Use a standard daily account
  1. Open System Settings -> Users & Groups.
  2. Create a new standard account for daily use, or convert the daily account to standard after creating a separate admin account.
  3. Keep one administrator account for maintenance.
  4. Have the trusted person hold the administrator password if you need lockout.
  5. Use the standard account for daily browsing and work.
  6. Test app installation, browser installation, and Screen Time changes from the standard account.

Expect the browser-installation test to fail, in the sense that it will succeed. A standard account on macOS still lets you put an app in your own home folder or run one from Downloads. The standard account is worth doing because it protects system-wide changes such as hosts files, profiles, and policy, but it is not an app-install block. Apple's own guidance reflects this: enabling Lock Screen Time Settings prompts you to convert an administrator account to standard, because Screen Time was never designed to hold against an admin.

Limit a specific browser you cannot remove

macOS has no allowlist of permitted applications in the normal settings. The old Parental Controls feature that did this was retired, and the current App & Feature Restrictions pane covers only a handful of Apple features, none of them third-party apps. The one usable lever is App Limits.

  1. Open System Settings -> Screen Time -> App Limits.
  2. Add a limit for the browser you want restricted and set it to the one-minute minimum.
  3. Turn on Block at end of limit. Without this the limit is only a notification.
  4. Confirm a Screen Time passcode is set, held by the trusted person. Without a passcode the block can be dismissed.
Understand what this does and does not buy. The app still opens for that first minute. The limit applies to one named application, so it does nothing about a different browser installed afterwards, and you cannot pre-emptively limit a browser that is not installed yet. There are documented reports of Screen Time limits and Downtime failing to hold against Chrome on recent macOS. This is a speed bump for a cooperative user, not a control against a determined one. For a real block on a Mac, use device management or filter at the network layer.

How to know this level is enough

  1. The obvious sites are blocked in every browser left on the device.
  2. You cannot install a new browser without approval or an admin password.
  3. You cannot change the filter from the daily account.
  4. You have tested Wi-Fi, cellular data, guest mode, and secondary accounts where they exist.
If any item fails, go to Friction. If you know how to undo the setup and still have the credentials, go to Lockout.

Official docs

After Guardrails